Lecture 9 — Comprehensive Exam Summary
Guest Lecture — Product Security in Practice (Toreon)
Maxim Baele · Cyber Resilience Act · OWASP SAMM · Secure Development Lifecycle
Overview
Guest lecture by Maxim Baele, Principal Consultant for Product Security at Toreon. Also: OWASP Belgium
chapter leader, OWASP SAMM core team member, OWASP EU Board, OWASP Regulations & Standards
Liaison.
Slide: Maxim's roles in OWASP — bridge-builder
Lecture agenda: context for product security, the Cyber Resilience Act (CRA), OWASP SAMM, SAMM in
practice.
How to build secure products
Slide: 'How to draw an owl' meme — policies ≠ secure products
Organisations think 'draft some policies' is sufficient — but step 2 is 'build the rest of the f***ing owl'. SAMM
fills that gap.
EXAM TIP: Likely exam material: CRA timing/scope/requirements; SAMM 5 business functions × 3
practices each; Security Champion role; SDL phases.
Lecture 9 — ICT Service Management — Page 1
, Part 1 — Context
Slide: Information security definition
Term Definition
Information security Set of procedures and tools to protect sensitive enterprise info. Covers
physical/env, access control, cybersecurity.
Formalisation timeline:
• 1980s — Orange Book (US DoD)
• 1990s-2010s — cybersecurity evolves as sub-domain
• 2020s — Supply Chain Security AND PRODUCT SECURITY emerge as new sub-domains
Lecture 9 — ICT Service Management — Page 2